lets servers experiment with policies by monitoring (rather than enforcing) a policy
Quick facts
Description
lets servers experiment with policies by monitoring (rather than enforcing) a policy
Syntax
Content-Security-Policy-Report-Only: default-src 'self'; report-uri /csp-report
Frequently asked questions
lets servers experiment with policies by monitoring (rather than enforcing) a policy
It is classified as a response header and can appear in requests or responses depending on context.
Sources & standards
Updated 2026-08-18